Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65m7-qc75-24vh

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.

aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.

EPSS

Процентиль: 37%
0.00158
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 16 лет назад

aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.

EPSS

Процентиль: 37%
0.00158
Низкий

Дефекты

CWE-20